Maxb's vulnerability footprint centers on its MaxBoard product, a web-based collaboration or communication platform characterized by application-layer input-handling weaknesses. The recurring exposure pattern reflects classic web-application risks including SQL injection, cross-site scripting, unrestricted file uploads, and authentication bypass via alternate paths, consistent with the input-validation and access-control demands of user-facing web services. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Maxb over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-26634CRITICAL SQL injection and file upload attacks are possible due to insufficient validation of input values in some parameters and variables of files compromising Maxboard, which may lead to | Jun 2, 2022 | 9.8 | 30 | NO | NO |
CVE-2021-26633CRITICAL SQL injection and Local File Inclusion (LFI) vulnerabilities in MaxBoard can cause information leakage and privilege escalation. This vulnerabilities can be exploited by manipulati | Jun 2, 2022 | 9.8 | 30 | NO | NO |
CVE-2021-26636CRITICAL Stored XSS and SQL injection vulnerability in MaxBoard could lead to occur Remote Code Execution, which could lead to information exposure and privilege escalation. | Jun 23, 2022 | 9.6 | 29 | NO | NO |
CVE-2021-26628MEDIUM Insufficient script validation of the admin page enables XSS, which causes unauthorized users to steal admin privileges. When uploading file in a specific menu, the verification of | Apr 26, 2022 | 6.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Maxb.
Media articles that mention a CVE ID that affects a product developed by Maxb — matched by CVE ID, not by vendor name.